August 1, 2026

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaign Storm-2945 and Midnight Blizzard CaptiveCrunch tradecraft and tooling How to protect against CaptiveCrunch activity Microsoft Defender detections and hunting guidance […]
July 17, 2026

ACR Stealer: Two observed intrusion chains amid increased threat activity

In this article Campaign 1: WebDAV-based ClickFix with Python loaders and blockchain C2 Campaign 2: MSHTA-initiated PowerShell chain with steganographic payload delivery Mitigation and protection guidance […]
May 7, 2026

ClickFix campaign uses fake macOS utilities lures to deliver infostealers

Microsoft researchers continue to observe the evolution of an infostealer campaign distributing ClickFix‑style instructions and targeting macOS users. In this recent iteration, threat actors attempt to […]